Quickstart
This runs curral with the example configuration from the repository: two
local DuckDB databases (sales and logs) and three users, admin,
analyst and etl. You need Docker and git.
-
Start the server.
Terminal window git clone https://github.com/lucasapassos/curral && cd curraldocker run --rm -p 127.0.0.1:8080:8080 \-v "$PWD/examples:/etc/curral:ro" -e CURRAL_DATA=/var/lib/curral \lucasapassos/curral serve \--catalog /etc/curral/catalog.yaml \--users /etc/curral/users.yaml \--policy /etc/curral/policy.rego --policy /etc/curral/roles.json -
Create a table as
admin. In another terminal:Terminal window curl -u admin:admin-pw localhost:8080/v1/query \-d '{"sql": "CREATE TABLE orders AS SELECT range AS id, range * 10 AS amount FROM range(5)"}' -
Read it as
analyst.Terminal window curl -u analyst:analyst-pw 'localhost:8080/v1/query?format=csv' \-d '{"sql": "SELECT * FROM orders"}' -
Try to write as
analyst, without running anything.dry_runasks the policy for its decision and explains it:Terminal window curl -u analyst:analyst-pw localhost:8080/v1/query \-d '{"sql": "DELETE FROM orders", "dry_run": true}'{"dry_run":true,"decision":"deny","decided_by":"policy","statement_type":"DELETE","tables":["sales.main.orders"],"targets":["sales.main.orders"], ...} -
See what the analyst can query.
Terminal window curl -u analyst:analyst-pw localhost:8080/v1/schema
Next steps
Section titled “Next steps”- Connect your own databases or an Iceberg lake.
- Create real users and write your policy.
- Deploy to a server with automatic HTTPS.